Download Latest Version agentguard_1.3.0_windows_amd64.zip (12.9 MB) Google Add to Preferred Sources
Home / v1.1.1
Name Modified Size InfoDownloads / Week
Parent folder
agentguard-v1.1.1.cdx.json 2026-09-24 18.5 kB
agentguard-v1.1.1.spdx.json 2026-09-24 28.4 kB
AgentGuard v1.1.1 source code.tar.gz 2026-09-24 1.2 MB
AgentGuard v1.1.1 source code.zip 2026-09-24 1.4 MB
README.md 2026-09-24 6.0 kB
Totals: 5 Items   2.7 MB 0

AgentGuard 1.1.1 — Release Notes

Released: 2026-09-23 Headline: A patch release that corrects what the docs got wrong about names, addresses and examples, and closes one proxy bind check. The TypeScript SDK is on npm for the first time, as @lictorate/agentguard.

If you sent a security, conduct or support report to cauaferraz@gmail.com, it was never received. That address doesn't exist; earlier docs misspelled it. Please resend to cauaferrazp@gmail.com.


Why this release exists

An audit checked every install command, contact address, example config and documented behaviour against what actually exists. Most of what it found was in the docs, and some of it pointed users at things that aren't ours or don't exist:

  1. The TypeScript install command named someone else's package. The docs said npm install @agentguard/sdk. That npm package belongs to an unrelated project; the AgentGuard SDK had never been published to npm.
  2. The security contact address didn't exist, so vulnerability reports sent to it went nowhere.
  3. Three release notes said to docker pull an image that was never published.
  4. The example MCP configs launched a fetch server that has never existed on npm, and the default policy denied every call to the fetch and GitHub examples even after approval.
  5. One code bug: agentguard-llm-proxy --listen :PORT started on every network interface with no inbound auth.

What changed

LLM API Proxy: --listen :PORT needs --proxy-api-key

A listen address with no host binds every interface, but the proxy treated it as loopback and skipped its rule that non-loopback binds require --proxy-api-key. It now refuses to start (exit status 2) and suggests 127.0.0.1:PORT. If you ran the proxy this way on a reachable host, anyone who could reach the port could send requests through it to your configured provider, each one policy-checked and audited under the proxy's AgentGuard API key.

TypeScript SDK on npm as @lictorate/agentguard

:::bash
npm install @lictorate/agentguard@1.1.1

:::ts
import { AgentGuard } from '@lictorate/agentguard';

This first version was published by hand; from the next release, GitHub Actions publishes it through npm trusted publishing, with provenance.

Example MCP configs and the default policy

  • The example configs for Claude Desktop, Cursor, Cline, Continue and Zed launch the official servers: uvx mcp-server-fetch and GitHub's ghcr.io/github/github-mcp-server image. Each guide lists the launcher (npx, uvx or docker) each upstream needs.
  • configs/default.yaml sends fetch and GitHub calls to human approval. Approved fetches still pass through the network allow-list; approved GitHub calls run.

Builds

  • go install builds show the update notice from the interactive subcommands, as documented, and agentguard version prints module vX.Y.Z or a git revision instead of dev. serve still never makes the check; AGENTGUARD_NO_UPDATE_CHECK=1 opts out.
  • make docker-run passes AGENTGUARD_API_KEY, which the container needs to listen on its published port, and stops with an explanation when the variable is unset.
  • agentguard status says when the server was started without --dashboard instead of printing a JSON decode error.

Documentation

Corrected against the code and, where it mattered, against a running server: the MCP and LLM proxy quickstarts, the MCP Gateway and LLM API Proxy references, deployment (Compose now builds the image; the Kubernetes example gained the --policy flag it needed to start), the API reference (SSE event types, status codes, and the previously undocumented POST /v1/audit), both SDK references, the CLI reference, the adapter compatibility matrix, the Go and Node version floors, and SECURITY.md, which now supports the 1.1.x line. The hot-path latency rules CI enforces are now public in CONTRIBUTING.md (github.com).

Corrections to earlier releases

Earlier CHANGELOG entries, release notes and MIGRATION.md are corrected in place, each with a (Corrected in v1.1.1: …) note: the contact address; the TypeScript SDK was not on npm at 0.5.2, 0.9.0 or 1.0.0; no Docker image was ever published; v0.7.0 and v0.4.1 were never published; and links to a design document that was never committed.


Breaking changes

None in the public API: no exported Go identifier, config key, route, wire field, audit format or policy schema changed.

Two behaviour changes can affect an existing setup:

  • --listen :PORT on the LLM proxy now refuses without --proxy-api-key. This is a fail-closed correction.
  • The shipped configs/default.yaml changed for the fetch and github MCP namespaces. A copy you made earlier is unaffected.

Upgrade notes

  • Binaries and Python SDK: a swap; nothing on disk changes.
  • TypeScript SDK: install @lictorate/agentguard and change imports from @agentguard/sdk.
  • LLM proxy: change --listen :PORT to 127.0.0.1:PORT, or add --proxy-api-key.
  • Rollback to 1.1.0 is safe, but brings back the --listen :PORT hole.

Details: MIGRATION.md § v1.1.0 → v1.1.1 (github.com).


Get started

:::bash
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard@v1.1.1
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard-mcp-gateway@v1.1.1
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard-llm-proxy@v1.1.1

pip install --upgrade "agentguardproxy==1.1.1"
npm install @lictorate/agentguard@1.1.1

# Docker: no image is published; build one from the repository's Dockerfile
docker build -t agentguard:1.1.1 .

Full change list: CHANGELOG.md § 1.1.1 (github.com).

Source: README.md, updated 2026-09-24